Built in the 60s. Still Running the World.

Recently, I switched internet service provider and overhauled my home network setup.

New network controller. Different topology. Rethinking segmentation and security.

It felt “modern.” Cutting edge, even.

And yet — while reading Where Wizards Stay Up Late by Katie Hafner and Matthew Lyon — I was reminded of something humbling:

Most of what makes my network function today was conceived in the 1960s and 70s.

Packet switching. TCP/IP. Distributed resilience.
The foundations laid by ARPA and the pioneers behind ARPANET are still carrying our traffic, our data, our businesses.

We’ve added layers of abstraction, security, and convenience.
But the architectural principles? Still going strong.

It’s a powerful reminder: real progress isn’t always about constant reinvention.
Sometimes it’s about building something so fundamentally sound that it survives decades of change.

As internal auditors working in IT and digital environments, that’s worth reflecting on.

What foundations are we helping to build today that will still matter in 30 years?

#technology #cybersecurity #internalaudit #digitaltransformation #historyoftechnology #networking #ITgovernance


Range

Currently reading Range by David Epstein. A timely reminder for internal auditors.

Epstein argues that deep specialization often narrows the solution space. Complex problems, the kind that live in grey areas rather than checklists, are frequently solved by people coming from outside the immediate field.
That resonates with how our profession is often assessed.

I regularly get asked: “Have you performed this specific audit before?”
Perhaps the more interesting question is: “Have you not done it before?”

Because not having audited something before can mean fewer assumptions, less attachment to legacy approaches, and more curiosity about what might be hidden one layer deeper.

Over-specialisation can start to resemble a Russian matryoshka doll: each layer familiar, each step inward smaller, tighter, and more predictable. Useful, but limiting.

Internal audit is not about repeating known routines. It’s about sense-making in complexity, connecting dots across domains, and seeing patterns others miss.

Range, not just depth, is a feature, not a bug.

Amplifying the Rhythm of Business: The Role of Internal Audit

As a freelance internal auditor, I often find myself contemplating the essence of our role and how we can truly add value to the organizations we serve. It’s not always easy to articulate this, especially when the business side may not fully grasp the function of internal audit.

The Institute of Internal Auditors (IIA) defines internal auditing as “an independent, objective assurance and advisory service designed to add value and improve an organization’s operations.” While this definition is accurate, it doesn’t always resonate with everyone. Believe me, I’ve tried explaining this to my mom and my 7-year-old daughter, and they’re still trying to figure out what I do!

Recently, I came across a video of Viktor Wooten, arguably the world’s best bass player, explaining the role of a bass player in a band’s rhythm section. He said, “I am going to reshape his groove and make it sound better”, “My job is not just to play with him, my job is to make him sound BETTER.”

This struck a chord with me. As internal auditors, our role is akin to that of a bass player in a band. We’re not just there to keep time; we’re there to enhance the rhythm, to make the organization ‘sound’ better. We audit, we advise, and we groove with the organization, helping it to perform its best tune!

What are your thoughts on this analogy? I’d love to hear your insights.